SECURITY OVERVIEW

YOUR DATA STAYS UNDER YOUR CONTROL.

Automation runs on your machine. Construction sources stay in the authenticated workspace. SEO uses approved public or first-party evidence. Customer-visible actions wait for human approval.

// SUPPORT EVIDENCE

What support sees by default

The support bundle is meant to prove operational state without exposing the customer records that caused the work.

Health checks

Doctor checks, status summaries, version, platform, configured folder paths, and release posture.

Operational counts

Failed-job counts, log counts, archive counts, impact counts, and run-state summaries.

Redacted identifiers

Non-reversible fingerprints may identify repeated files or cases without including the source data itself.

Included in default support evidence

  • Install and readiness receipts.
  • Version, platform, and configured local folder checks.
  • Status, health-check, failed-job, log, archive, and impact counts.
  • Redacted case metadata and non-reversible fingerprints.

Excluded by default

  • Raw invoices, generated PDFs, emails, and line items.
  • Customer names, full customer lists, and bank rows.
  • Email passwords, OAuth tokens, and mailbox credentials.
  • Source spreadsheets unless the customer explicitly sends one for review.
// DATA RETENTION

Retention is bounded by where the data lives

Local workflow artifacts stay under customer control. Hosted discovery records use fixed limits and an operator-run purge.

Customer machine

  • Local logs: 30 days. Operational logs only.
  • Local generated outputs: 90 days. Reports, PDFs, and other generated output.
  • Local errors: 60 days. Failed-run artifacts and error sidecars.
  • Local archives: customer controlled. No automatic deletion unless the customer configures a window.

Hosted discovery

  • Hosted report uploads: 90 days. Cloudflare object storage removes the generated report and redacted findings.
  • Upload tokens: 30 days maximum. A token is also consumed after its accepted upload.
  • Intake and transaction metadata: 24 months. This includes quote, payment, webhook, and fulfillment records.
  • Raw source files: not accepted. Customer spreadsheets, invoices, bank rows, and mailbox data remain local.

To make a deletion request, email support@vigilautomation.com. Vigil confirms the request through the support relationship and records completion.

LOCAL CONTROLS

Controlled exports require customer intent

Dataset exports are not the default support path. When a customer chooses to create one, the export is explicit and should contain operational event metadata only, not raw financial records.

  • Secrets stay in the OS keychain

    Where supported, mailbox credentials are stored by the operating system rather than in plain text.

  • Dashboard binds to localhost

    The operator dashboard is meant for the local machine by default, not the public internet.

  • Security scans and SBOM in release

    Release checks include security scanning and a software bill of materials for installed packages.

  • Human approval remains the boundary

    Support diagnostics help the operator. They do not send customer-visible messages or change workflows alone.

Review the data boundary before the first engagement

Vigil starts with the narrowest approved access, redacted support evidence, and a defined scope. Security questions should be answered before automation, project intake, or website changes begin.